FINDING · DETECTION

Classification from the first 5 packets × 320 bytes (1600-byte burst) achieves near-perfect accuracy across Tor (F1=0.9990), VPN (F1=0.9871), malware (F1=0.9954), and IoT attack traffic (F1=0.9966), with IP addresses masked and only header and initial payload retained. The earliest portion of each packet provides sufficient discriminative information for a classification decision made within the first kilobyte of a flow.

From 2026-kulatilleke-mambanetburst-direct-byte-levelMambaNetBurst: Direct Byte-level Network Traffic Classification without Tokenization or Pretraining · §III-A, §V-A, Table II–III · 2026 · arXiv preprint

Implications

Tags

censors
generic
techniques
ml-classifierdpi
defenses
torpluggable-transportobfs4

Extracted by claude-sonnet-4-6 — review before relying.